Session Theft Threat Escalates as 4,532 Firms Targeted
Mirage2FA campaign hit 4,532 companies, bypassing MFA and stealing sessions.
The Mirage2FA phishing operation has been quietly targeting Microsoft 365 environments since 2024, and new research from ANY.RUN suggests the campaign’s reach is far broader than previously understood. The commercial phishing-as-a-service toolkit has potentially impacted 4,532 unique organization email domains, with 63.7% of victims located in the United States. But the numbers only tell part of the story; the technique behind the attacks reveals a shift in how cybercriminals approach authentication.
Bypassing 2FA Through Legit Flows
Mirage2FA doesn’t rely on breaking encryption or exploiting obscure vulnerabilities. Instead, it abuses legitimate Microsoft 365 login flows, tricking users into entering their credentials on convincing fake pages. The attackers then intercept both the password and the session cookie, effectively bypassing two-factor authentication (2FA) because they hijack the authenticated session itself.
According to ANY.RUN’s research, 48% of targeted email addresses were potentially compromised. This isn’t just about stolen passwords; attackers gain access to authenticated sessions, allowing them to move laterally through connected services including SSO-linked applications.
Scope of the Campaign
The geographic distribution of victims is wide. The United States leads with 63.7% of total victims, but Mirage2FA activity has been observed in India, Singapore, the United Kingdom, Canada, Saudi Arabia, South Africa, and other countries. The campaign’s corporate reach spans multiple industries, with technology, manufacturing, and education among the most targeted sectors.
ANY.RUN’s research uncovered over 9,000 potential compromise events involving cookie and password theft, SSO logins, and 2FA bypass. These aren’t isolated incidents; they point to a sustained, organized effort exploiting gaps in authentication and session management.
The Danger of Session Hijacking
The core risk isn’t just password theft—it’s session hijacking. When an attacker steals a session cookie, they bypass the need to know the password at all. They essentially become the user, with all the access that implies. This makes the attack particularly insidious because conventional security measures like MFA are rendered ineffective.
ANY.RUN’s analysis highlights how AiTM (adversary-in-the-middle) attacks can exploit these gaps even when 2FA is deployed. The impact extends beyond the initial account, reaching SSO-connected apps and internal workflows, increasing the attack radius and containment costs.
Treating Session Theft as Identity Incident
According to ANY.RUN, session theft should be treated as an identity incident, not just a credential compromise. Teams need to revoke compromised sessions and tokens, investigate activity tied to the affected identity, and avoid relying solely on password resets.
The research emphasizes that attackers can access corporate environments through hijacked sessions, making swift remediation difficult. This is why they stress that sessions are the new battleground—securing them requires more than traditional MFA.
Detection via Sandboxing
To counter such campaigns, ANY.RUN suggests integrating sandboxing into security workflows. Their Interactive Sandbox can analyze suspicious attachments and URLs in isolation, exposing redirects, scripts, WebSocket activity, and fake Microsoft 365 login pages. This helps SOC teams identify phishing behavior before it leads to account compromise.
ANY.RUN claims that their approach can detect threats in 14 seconds and cut MTTR by 21 minutes per case. While these metrics come from the vendor, they underscore the potential value of automated analysis in spotting such attacks early.
From IOCs to Infrastructure
Beyond individual indicators of compromise, ANY.RUN recommends investigating recurring loaders, encoded data, suspicious WebSocket activity, and related infrastructure to reveal connections to wider campaigns. Their Threat Intelligence Feeds provide malicious indicators in real time, complementing behavioral detections. Analysts can then use Threat Intelligence Lookup to pivot from URLs, domains, IPs, and files to related infrastructure.
With threat data from 16,000+ organizations, the goal is to turn isolated IOCs into actionable intelligence. This approach helps connect seemingly disparate attacks to a single campaign, enabling proactive defense.
What This Means for Enterprises
The Mirage2FA campaign illustrates how phishing has evolved beyond simple credential theft. By hijacking Microsoft 365 sessions, attackers bypass conventional MFA and gain access through trusted identities. For businesses, the takeaway is clear: phishing-resistant authentication, behavioral detection, and response procedures designed for session theft are no longer optional.
The scale of the campaign—thousands of organizations, mostly in the US—suggests that session hijacking is becoming a preferred method for attackers. Companies must treat session theft as seriously as any other identity compromise, because the consequences can ripple across their entire cloud environment.
Sources
- The Hacker News Original source
Continue Reading
Global Dragnet Hits West African Cybercrime Rings
Operation Jackal IV arrests 58, targets Black Axe syndicate across 22 countries over eight months.
Fake Codex Site Lures macOS Users via Google Ads
Cato Networks found a campaign abusing Google Sites to spread macOS malware through ClickFix tactics.
Teams Helpdesk Scam Spreads SynkLoader Backdoor
Cybercriminals are using fake IT helpdesk messages on Microsoft Teams to deliver a new backdoor malware, researchers warn.